Security / GDPR and Privacy Act readiness

GDPR and Australian Privacy Act readiness.

A European customer or a privacy review put your data handling in question. This is the engineering side of it.

Included

What the work covers

  • Data map: what is held, where it lives, who can reach it.
  • Lawful basis and consent records under GDPR.
  • Australian Privacy Principles and the Notifiable Data Breaches scheme.
  • Cross-border transfer mechanisms and residency decisions.
  • Retention, deletion and subject request handling that actually runs.
Excluded

What we do not do

  • Legal advice. We are engineers, not a law firm.
  • Acting as your Data Protection Officer.
  • Representing you to a regulator.
The principles this work maps to

Named, so you can check us.

Privacy Act 1988 (Cth) Schedule 1, the thirteen Australian Privacy Principles, and Part IIIC, the Notifiable Data Breaches scheme. Where GDPR also applies, the equivalent obligations are handled alongside rather than instead.

Australian Privacy Principles
ReferenceWhat it requiresWhat readiness produces
APP 1Open and transparent management of personal informationA privacy policy that matches what the system does.
APP 3Collection of solicited personal informationA data map showing what is collected and why.
APP 5Notification of the collection of personal informationCollection notices at the point of collection.
APP 6Use or disclosure of personal informationPurpose limits enforced in the system, not only in the policy.
APP 8Cross-border disclosure of personal informationTransfer mechanisms and residency decisions, recorded.
APP 11Security of personal informationAccess control, retention and deletion that actually run.
APP 12Access to personal informationA subject access process with a timeframe.
APP 13Correction of personal informationCorrection that propagates beyond the primary database.
Notifiable Data Breaches
ReferenceWhat it requiresWhat readiness produces
Part IIICNotifiable Data Breaches schemeAn assessment process that starts on suspicion, not on confirmation.
Part IIICEligible data breach assessmentThirty days to assess, so the clock starts before you know the answer.
Part IIICNotification to the Commissioner and to individualsA statement you can produce under pressure.

Source. OAIC Australian Privacy Principles. Identifiers verified against the primary source, not quoted from a summary.

There is no certificate for the Privacy Act or for GDPR. The deliverable is a data map, a gap list against the principles above and a remediation plan. Legal interpretation belongs to your lawyer, and we will say so rather than guess.

Failure modes

What usually goes wrong.

  • A data map drawn once and never matched against production.
  • Deletion requests handled in the app but not in the warehouse or the backups.
  • Consent recorded without the version of what was consented to.
  • A breach plan that has never been run as an exercise.
Questions before you book

Practical answers.

Does the Australian Privacy Act apply to us?

It applies to most organisations over the turnover threshold and to some under it. The 2024 amendments raised penalties and expectations. Confirm with your legal adviser.

Does GDPR apply to an Australian company?

It can, if you offer goods or services to people in the European Union or monitor their behaviour. Where you are incorporated is not the test.

Do you provide legal advice?

No. We do the engineering work: data mapping, access controls, retention, deletion and breach readiness. Your lawyer covers the legal position.

Is this a certification?

No. There is no certificate for GDPR or the Privacy Act. The output is a data map, a gap list and a remediation plan.

Privacy work overlaps the other regimes more than buyers expect. APP 11 covers much of the same ground as ISO 27001 readiness, and a customer asking for evidence usually wants SOC 2 readiness. Where personal information sits in a cloud account you cannot fully describe, a cloud security review is the faster way to find it, and our own trust centre shows the same questions answered about us.

Let’s scope it

Ready to scope gdpr and privacy act readiness?

Send the requester wording and your deadline. We will confirm scope and fee before any work starts.

Request a quote

Last reviewed: